logo

POISON_CARP__2020__New_Android_Spyware_ActionSpy_Revealed_via_Phishing_Attacks_from_Earth_Empusa_-_TrendLabs_Security_Intelligence_Blog.pdf

ID: 8577dd41-72b9-4c4b-8798-b78f2cfb0f44

STIX ID: report--8577dd41-72b9-4c4b-8798-b78f2cfb0f44

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2020-06-15

Last Modified Date: 2020-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro researchers disclose ActionSpy, an Android spyware linked to the Earth Empusa (POISON CARP) threat actor that was distributed via phishing pages and watering-hole compromises; ActionSpy impersonates a legitimate Uyghur video app, abuses Android Accessibility to harvest chat logs from WeChat/QQ/WhatsApp/Viber, performs broad device data collection and encrypted C2 communications, and is associated with iOS exploit chains used in the wild — the report includes technical analysis, IOCs (domains, C2 URLs, SHA256), certificate and file metadata, and a MITRE ATT&CK mapping.